Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update SmartIT Desktop Manager to version 11 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lightstar
Lightstar smartit Desktop Manager |
|
| Vendors & Products |
Lightstar
Lightstar smartit Desktop Manager |
Fri, 04 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host. | |
| Title | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-09-04T18:25:32.208Z
Reserved: 2026-09-03T10:00:27.134Z
Link: CVE-2026-85149
Updated: 2026-09-04T17:36:25.477Z
Status : Received
Published: 2026-09-04T03:17:46.190
Modified: 2026-09-04T19:17:31.220
Link: CVE-2026-85149
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:20:41Z